CVE-2026-77426
Last modified
CVE-2026-77426 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting it, allowing authenticated users to modify segment assignments without UPDATE_FEATURE_STRATEGY permission for the target project and environment. GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants does not bind the requested feature to projectId, allowing cross-project variant configuration disclosure. GET .../strategies/:strategyId uses strategyId without validating the project and feature context, allowing cross-project strategy configuration disclosure. getEnvironmentInfo does not validate that the requested feature belongs to the supplied project, allowing cross-project environment information disclosure. PUT /:projectId/tags accepts feature identifiers without verifying that they belong to the URL project, allowing cross-project tag modification. This issue is fixed in version 8.0.3.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unleash | unleash | < 8.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-77426?
How severe is CVE-2026-77426?
How do I fix CVE-2026-77426?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7742A flaw has been found in CodeAstro Online Classroom 1.0. The…6.3
- CVE-2026-77420JLine is a Java library for handling console input. From 3.0…5.5
- CVE-2026-77421JLine is a Java library for handling console input. From 3.0…6.5
- CVE-2026-77422JLine is a Java library for handling console input. From 3.0…7.5
- CVE-2026-77423JLine is a Java library for handling console input. From 3.0…7.5
- CVE-2026-77425Unleash is an open-source feature management platform. Prior…4.3
- CVE-2026-7743A vulnerability has been found in CodeAstro Online Classroom…6.3
- CVE-2026-77438Trilium is an open-source hierarchical note-taking applicati…7.5
- CVE-2026-7744A vulnerability was found in CodeAstro Online Classroom 1.0.…6.3
- CVE-2026-7745A vulnerability was determined in CodeAstro Online Classroom…6.3
- CVE-2026-77454Incorrect Authorization vulnerability in ash-project ash_sql…5.9
- CVE-2026-7746A vulnerability was identified in SourceCodester Web-based P…6.3
Are you affected by CVE-2026-77426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
